VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,531)

page 693 of 727
  • CVE-2026-59146HigJul 21, 2026
    risk 0.00cvss 7.8epss 0.00

    Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator sph_validate_header checks the header scalars and region layout against…

  • CVE-2026-16225MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. The manipulation of the argument PDULength results in out-of-bounds write. The attack can be executed…

  • CVE-2026-16095HigJul 18, 2026
    risk 0.00cvss 8.8epss 0.00

    A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote.…

  • CVE-2026-44436HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.00

    Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack through connection state corruption. In QUIC Invariants, the maximum length of a Connection ID is 255…

  • CVE-2026-15422CriJul 16, 2026
    risk 0.00cvss epss 0.01

    The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote,…

  • CVE-2026-10589MedJul 16, 2026
    risk 0.00cvss 6.0epss 0.00

    A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

  • CVE-2026-10587MedJul 16, 2026
    risk 0.00cvss 6.0epss 0.00

    A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

  • CVE-2026-50144HigJul 15, 2026
    risk 0.00cvss 7.1epss 0.00

    ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows an out-of-bounds heap write in ncnn::ParamDict::load_param() when Net::load_param() loads a malicious…

  • CVE-2026-40953MedJul 15, 2026
    risk 0.00cvss 4.4epss 0.00

    CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.

  • CVE-2026-62349HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.00

    TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte…

  • CVE-2026-48337HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48336HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48335HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48370HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48369HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48367HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48366HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48343HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48341HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48311HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.